<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: ISE: No more logs after having replaced PSN in Network Access Control</title>
    <link>https://community.cisco.com/t5/network-access-control/ise-no-more-logs-after-having-replaced-psn/m-p/4737077#M578779</link>
    <description>&lt;P&gt;Thanks for this feedback.&lt;/P&gt;
&lt;P&gt;Another point which must also be taken into account:&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;We could not reimport the ISE Messaging Service certificate on the new equipments.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Can this have an impact on the logs knowing that the option [Use "ISE Messaging Service" for UDP Syslogs delivery to MnT ] is disabled?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Mon, 12 Dec 2022 13:37:26 GMT</pubDate>
    <dc:creator>jds5</dc:creator>
    <dc:date>2022-12-12T13:37:26Z</dc:date>
    <item>
      <title>ISE: No more logs after having replaced PSN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-no-more-logs-after-having-replaced-psn/m-p/4736923#M578772</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt;Following the reset of the /opt partition which was full (100%) on MNT, we no longer have Splunk logs on 2 new PSN 3695&lt;/P&gt;
&lt;P&gt;while the other 4 PSN(3595) continue to work correctly.&lt;/P&gt;
&lt;P&gt;There are collection log Errors:&lt;/P&gt;
&lt;P&gt;The ISE MNT collector process is unable to persist the audit logs generated from the Policy Service nodes.&lt;/P&gt;
&lt;P&gt;The current version is: 2.7.0.356 P5&lt;/P&gt;
&lt;P&gt;BR,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 10:53:16 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-no-more-logs-after-having-replaced-psn/m-p/4736923#M578772</guid>
      <dc:creator>jds5</dc:creator>
      <dc:date>2022-12-12T10:53:16Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: No more logs after having replaced PSN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-no-more-logs-after-having-replaced-psn/m-p/4736957#M578773</link>
      <description>&lt;P&gt;I found this bug&amp;nbsp; CSCvv08466 which seems to correspond but it's already fixed in patch 3&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 11:00:56 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-no-more-logs-after-having-replaced-psn/m-p/4736957#M578773</guid>
      <dc:creator>jds5</dc:creator>
      <dc:date>2022-12-12T11:00:56Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: No more logs after having replaced PSN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-no-more-logs-after-having-replaced-psn/m-p/4736959#M578774</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;- Probably a bug as these reports seem indicative&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch?pf=prdNm&amp;amp;kw=The%20ISE%20MNT%20collector%20process%20is%20unable%20to%20persist%20the%20audit%20logs%20generated%20from%20the%20Policy%20Service%20nodes&amp;amp;bt=custV&amp;amp;sb=anfr" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch?pf=prdNm&amp;amp;kw=The%20ISE%20MNT%20collector%20process%20is%20unable%20to%20persist%20the%20audit%20logs%20generated%20from%20the%20Policy%20Service%20nodes&amp;amp;bt=custV&amp;amp;sb=anfr&lt;/A&gt;&amp;nbsp;, also take care with 2.7&lt;FONT color="#FF0000"&gt;P&lt;U&gt;&lt;STRONG&gt;5&lt;/STRONG&gt;&lt;/U&gt;&lt;/FONT&gt; because of&amp;nbsp;&lt;A href="https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa00729" target="_blank"&gt;https://bst.cloudapps.cisco.com/bugsearch/bug/CSCwa00729&lt;/A&gt;&amp;nbsp; , consider stepping up (&lt;FONT color="#008000"&gt;&lt;EM&gt;installing higher patch&lt;/EM&gt;&lt;/FONT&gt;) as soon as possible ,&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;M.&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 11:02:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-no-more-logs-after-having-replaced-psn/m-p/4736959#M578774</guid>
      <dc:creator>Mark Elsen</dc:creator>
      <dc:date>2022-12-12T11:02:47Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: No more logs after having replaced PSN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-no-more-logs-after-having-replaced-psn/m-p/4737077#M578779</link>
      <description>&lt;P&gt;Thanks for this feedback.&lt;/P&gt;
&lt;P&gt;Another point which must also be taken into account:&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;We could not reimport the ISE Messaging Service certificate on the new equipments.&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN class="jCAhz ChMk0b"&gt;&lt;SPAN class="ryNqvb"&gt;Can this have an impact on the logs knowing that the option [Use "ISE Messaging Service" for UDP Syslogs delivery to MnT ] is disabled?&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 13:37:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-no-more-logs-after-having-replaced-psn/m-p/4737077#M578779</guid>
      <dc:creator>jds5</dc:creator>
      <dc:date>2022-12-12T13:37:26Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: No more logs after having replaced PSN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-no-more-logs-after-having-replaced-psn/m-p/4737081#M578780</link>
      <description>&lt;P&gt;this could not be done because on the new PSN, the ISE Messaging Service certificate used has a different domain name&lt;/P&gt;</description>
      <pubDate>Mon, 12 Dec 2022 13:40:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-no-more-logs-after-having-replaced-psn/m-p/4737081#M578780</guid>
      <dc:creator>jds5</dc:creator>
      <dc:date>2022-12-12T13:40:32Z</dc:date>
    </item>
    <item>
      <title>Re: ISE: No more logs after having replaced PSN</title>
      <link>https://community.cisco.com/t5/network-access-control/ise-no-more-logs-after-having-replaced-psn/m-p/4737095#M578781</link>
      <description>&lt;OL&gt;
&lt;LI&gt;Navigate to &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Logging&lt;/STRONG&gt;.&amp;nbsp; You should see that &lt;STRONG&gt;Use ISE Messaging Service for UDP Syslogs delivery to MnT&lt;/STRONG&gt; is enabled.&amp;nbsp; This is a new feature that was released in ISE 2.6 and I have run in to this issue.&amp;nbsp; You may need to regenerate these certificates after an upgrade.&lt;/LI&gt;
&lt;LI&gt;To fix this you need to generate new deployment-wide signed certificates.&amp;nbsp; This is a simple process that can be done by navigating to &lt;STRONG&gt;Administration &amp;gt; System &amp;gt; Certificates&lt;/STRONG&gt; and choosing &lt;STRONG&gt;Certificate Signing Requests&lt;/STRONG&gt; from the left menu&lt;/LI&gt;
&lt;LI&gt;Click the button for &lt;STRONG&gt;Generate Certificate Signing Requests (CSR)&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CharlieMoreton_0-1670852751126.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/170671i0F5B8380152FFF8C/image-size/medium?v=v2&amp;amp;px=400" role="button" title="CharlieMoreton_0-1670852751126.png" alt="CharlieMoreton_0-1670852751126.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;OL start="4"&gt;
&lt;LI&gt;In the Usage field, select that the Certificate(s) will be used for &lt;STRONG&gt;ISE Messaging Service&lt;/STRONG&gt;&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="IMS.png" style="width: 268px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/170678iC460F3CDAFBF349A/image-size/large?v=v2&amp;amp;px=999" role="button" title="IMS.png" alt="IMS.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;OL start="5"&gt;
&lt;LI&gt;Since this is an upgrade, ISE Messaging may not have been enabled previously, you need to select &lt;STRONG&gt;Generate CSR for ISE Messaging Service&lt;/STRONG&gt;&lt;/LI&gt;
&lt;LI&gt;Select ALL the ISE Nodes and fill out the certificate fields&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="CharlieMoreton_2-1670852751135.png" style="width: 400px;"&gt;&lt;img src="https://community.cisco.com/t5/image/serverpage/image-id/170673i6ABD6A29BAAD2ED0/image-size/medium?v=v2&amp;amp;px=400" role="button" title="CharlieMoreton_2-1670852751135.png" alt="CharlieMoreton_2-1670852751135.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;OL start="7"&gt;
&lt;LI&gt;Of course, you should follow any guidance and troubleshooting from the &lt;A href="https://www.cisco.com/c/en/us/td/docs/security/ise/2-7/upgrade_guide/Upgrade_Journey/Cisco_ISE_2_7_Upgrade_Journey.html" target="_self"&gt;Cisco Identity Services Engine Upgrade Guide, Release 2.7&lt;/A&gt;&lt;/LI&gt;
&lt;/OL&gt;</description>
      <pubDate>Mon, 12 Dec 2022 13:50:47 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-access-control/ise-no-more-logs-after-having-replaced-psn/m-p/4737095#M578781</guid>
      <dc:creator>Charlie Moreton</dc:creator>
      <dc:date>2022-12-12T13:50:47Z</dc:date>
    </item>
  </channel>
</rss>

